$40k? Lol. I’m poor and I’d have to think twice about disclosing it for that. How many government lists does having the ability to discover that type of exploit get you on? I bet Microsoft would claim damages of $1+ billion if someone used that type of exploit maliciously by damaging data and undermining customer confidence in Azure. What a joke. This should pay $1+ million.
“Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
51–60 of 92 posts
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#52Earlier quoted context omitted.
The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…
If companies have to outcompete criminals and intelligence agencies in the open market there will be no bug bounties, we'll just go back to the old way of doing things. The reality is that if an organization is using a managed database and doesn't have service-provider vulnerabilities as part of their threat model, they are naive and arguably negligent.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#53I always wonder if these types of vulnerabilities affect the most secret DoD contracts, or if those accounts are somehow sharded onto sufficiently separate systems/networks?
And when you're talking about "most secret" contracts, those are all classified systems, which are on totally separate networks in totally separate private data centers located on military installations. Unless you've figured out how to break strong symmetric encryption using hardware-generated, hardware-loaded, pre-shared keys controlled in military arms rooms, that means you need physical access. It doesn't necessarily mean you need to break into a military installation. You can always try to break into a contractor SCIF instead, but that still isn't all that easy. My wife once saw some AT&T contractors digging too close to the wrong fiber line at her facility when she was working for the Navy at a contractor site and unmarked black SUVs were there to take those guys away to God knows where within two minutes.
That said, I don't doubt people try. When I was at Raytheon working at a secure facility, a Chinese company bought the property across the street, built a hotel at exactly the same height with windows facing us, and it was conspicuously almost always empty. I don't think demand for hotel rooms was financing that place.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#54Whenever stuff like this happens I see people saying there should be legal consequences for leaking data. By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#55Earlier quoted context omitted.
If companies have to outcompete criminals and intelligence agencies in the open market there will be no bug bounties, we'll just go back to the old way of doing things. The reality is that if an organization is using a managed database and doesn't have service-provider vulnerabilities as part of their threat model, they are naive and arguably negligent.
Mid-range engineer at big tech makes $350k / year. I think having a vulnerability like this go to Microsoft instead of criminals is easily worth a few engineer-years. A $1M payout is just not unreasonable or even difficult for a $2.5T corporation.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#56Earlier quoted context omitted.
> By that logic should there be legal consequences for a company if someone breaks into their office and steals paper records? Comparing cloud storage and paper records is worse than comparing apples to oranges; it's comparing apples to celery. Sure they're both edible but they are vastly different organisms. And yes, there can be legal consequences for a company if someone breaks into their office and steals paper r…
An analogy of an analogy. Could somebody go one level deeper?
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#57I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#58Earlier quoted context omitted.
Because it is unethical and in most countries illegal :) But you are right. They should pay them more.
I wouldn’t use it maliciously, but I would honestly think twice about disclosing it. I think that’s especially true for anyone that doesn’t have a way to gain from the publicity.
That seems overly paranoid.
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#59Earlier quoted context omitted.
The context you're missing here is the company/research-team that found this are ex-MS employees who started a company (Wiz.io) to help other companies secure their cloud hosting/environments. This is some of the most pure-gold viral content marketing they can dream of, they don't care about the $40k at all, its just to acknowledge this is non-trivial.
The context you're missing is it doesn't matter. Next person to discover a similar vulnerability in Azure will have a choice: 1. Disclose to Microsoft for $40k 2. Disclose to an intelligence agency for several times that 3. Disclose to criminals for several times that, in turn The incentives are now publicly known to be misaligned, and as a potential Azure customer, I have to contend with the simple reality that a si…
Re: “Worst cloud vulnerability you can imagine” discovered in Microsoft Azure
#60I'm curious if Microsoft is suffering from a massive loss of generational expertise. At least right after XP we had to go through a security standdown where all code was reviewed and audited throughout the company. Subsequent features and services had to go through a pretty thorough security review at design time as well. Over the past few years the number of security fiascos has been increasing. Is the internal Secu…